China-linked hackers exploit Roundcube flaws CVE-2024-42009 and CVE-2025-49113 to spy on U.S. and Canadian researchers

A suspected China-aligned hacking group has been breaking into vulnerable Roundcube webmail servers at U.S. and Canadian universities to steal logins and plant backdoors. Proofpoint says the campaign, tracked as UNK_MassTraction, has run since May and targets physics, engineering, astrophysics, particle-physics, and national-security-related research organizations. Attackers use emails that trigger Roundcube cross-site scripting flaw CVE-2024-42009 to load the IceCube stealer, then abuse deserialization flaw CVE-2025-49113 to try to install the SquareShell PHP web shell or the VShell backdoor.
Why it matters: Universities and research groups handling sensitive science and national-security work may have had email accounts and mail servers compromised. Organizations using Roundcube should patch immediately, review mail-server logs for exploitation, and reset credentials and session cookies for potentially affected users.

Sources

Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
2026.07.08 97% relevant
This is the same underlying campaign and adds reporting that Proofpoint directly observed fewer than 10 universities targeted, estimates a few dozen total victims, says the campaign likely remains ongoing, and provides additional detail on the target set and IceCube-to-SquareShell/VShell attack chain.
Hackers exploit Roundcube flaw to spy on academic researchers
Bill Toulas 2026.07.08 100% relevant
This article establishes a distinct tracked story by tying active espionage intrusions to specific Roundcube CVEs, named malware payloads, and a defined victim set in academia and national-security-related research.
← Back to all stories